Device provisioning

Encrypted DNS profiles for Sanctuary devices. Private — not a public service.

These profiles route DNS over HTTPS to Quad9, a Swiss foundation that does not log source IP addresses and does not send EDNS Client Subnet. They apply on cellular and on every wifi network, including ones you do not control.

At home this is already handled — the gateway resolves over HTTPS for every device on the network. These profiles exist for everywhere else.

Install

iPhone / iPad → Open this page in Safari on the device, then tap here. Mac → Download, double-click, approve in System Settings.

iOS will not use the profile until you select it. After installing:

  1. Settings → General → VPN, DNS & Device Management → DNS
  2. Choose Quad9 Encrypted DNS

Skipping that step is the usual reason people conclude it did not work. Verify at on.quad9.net — it reports whether Quad9 is actually resolving for you.

If a captive portal will not load

Hotel and airport wifi that intercepts DNS can conflict with encrypted DNS. Set DNS → Automatic on the same screen, log in, then switch back. The same path removes the profile entirely — nothing here is locked.

Verifying what you downloaded

These profiles are signed, with an Apple Development certificate, so the install dialog names the signer rather than reading “Unverified”. Verified on macOS 2026-08-26. The signature also makes the file tamper-evident in transit, which a checksum alone does not. Check the file matches:

shasum -a 256 ~/Downloads/quad9-iphone-signed.mobileconfig

e0ed671308645ef54b6d39d1a4f2c4d1c2ada72754e9a388bb0313466b74e370  quad9-iphone-signed.mobileconfig
b378d3533f855acd3742500f4122b63bebd436f8d047a200ff25f5c1c94e5ad0  quad9-mac-signed.mobileconfig

Also served as /SHA256SUMS.